Courseiva
SDLC Automation →hardMultiple Choice

DOP-C02 SDLC Automation Practice Question

A team uses AWS CodePipeline to deploy a serverless application using AWS SAM. The pipeline includes a build stage that runs 'sam build' and a deploy stage that runs 'sam deploy'. The deployment fails with an error: 'The security token included in the request is invalid.' What is the MOST likely cause?

⚠ Common exam trap

Watch out — candidates often confuse IAM permission errors with template syntax or missing parameters, but the specific 'security token invalid' error points directly to an STS trust or assumption failure, not to CloudFormation validation or artifact issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM role used in the deploy stage does not have permission to assume the CloudFormation execution role.

The error 'The security token included in the request is invalid' typically occurs when the IAM role used by CodePipeline in the deploy stage lacks the necessary trust relationship or permissions to assume the CloudFormation execution role. In AWS SAM deployments via CodePipeline, the deploy action uses a specified IAM role to call CloudFormation, and if that role cannot assume the CloudFormation service role (or the CloudFormation role itself is misconfigured), the security token becomes invalid. This is a common misconfiguration when the pipeline's IAM role does not include the 'sts:AssumeRole' permission for the CloudFormation execution role ARN.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The build stage did not produce the correct output artifact.

    Why it's wrong here

    A missing or misnamed build output artifact is a data problem, not a credentials problem. CodePipeline reports this as an artifact resolution error on the Deploy stage, such as 'Artifact ... does not exist' or 'Unable to download artifact', typically before invoking CloudFormation. The error in this scenario is an invalid security token, which is raised when the AWS API call to CloudFormation or STS fails authentication/authorization, so the build artifact cannot be the cause.

  • ✗

    The SAM template has a syntax error.

    Why it's wrong here

    A SAM template syntax error would be caught during the build or package phase when `sam build` parses the template, producing a YAML parse error, unknown resource type, or invalid property error with a file and line number. CloudFormation would not report an invalid security token because the template never reaches an API call; even in CodePipeline, the validation error appears before the deploy action attempts to assume a role. Therefore a malformed template would yield a different, template-specific error message.

  • ✓

    The IAM role used in the deploy stage does not have permission to assume the CloudFormation execution role.

    Why this is correct

    CodePipeline's CloudFormation deploy action uses a service role to issue `sts:AssumeRole` for the CloudFormation execution role specified in the pipeline configuration. If the service role's policy lacks `sts:AssumeRole` permission on that execution role (or the execution role's trust policy does not allow the service role), the STS call fails with 'AccessDenied' or an invalid-token indication because the temporary credentials cannot resolve the requested role. This precisely matches the reported error, making it the root cause.

  • ✗

    The 'sam deploy' command is missing the '--capabilities' parameter.

    Why it's wrong here

    Omitting `--capabilities` from the `sam deploy` command causes CloudFormation to reject the change set with a 'requires capabilities: [CAPABILITY_IAM]' error, which is a template validation/authorization condition, not a security token failure. CodePipeline executes `sam deploy` as a shell command and does not see an invalid token for a capabilities-parameter omission. The error here is at the STS role-assumption layer, so a missing capabilities flag is an unrelated common mistake.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.